can anyone from Extreme tell me, when you plan to release a new feature version of XIQ OnPrem?
This is getting ridiculous, no big feature update for one and half year, we still have to use 21.1.x, so January 2021 version according to your scheme.
Solved! Go to Solution.
Allow me to simplify. As the bulletin says, "In certain configurations, an attacker could execute arbitrary commands with the privileges of the script." In IQVA, yes, c_rehash is present. However, IQVA does not use it in any process, the configurations required for exploit are non-existent, and access to the OS in any capacity to expose it is not exposed. Several other CVE's are being tackled in the January release, specifically CVE-2021-4034. And no, the January release is not a joke, and is currently tracking as follows:
@daniel1 I just spoke to the team that's doing it and you should see it in the next week or so. QA testing is complete, the final build approved, and release notes should be finalized today (2/23). Then we just have to work to get it posed.
While IQVA has been announced EOS, we are planning on a release of IQVA in the Dec/January timeframe. It will feature several bug fixes, updated features, support for DTLS 1.2, and new AP support for the new "-1" SKU's (no bluetooth).
Hi @BillL ,
are you guys serious with this? Security Advisory: SA-2022-010 – OpenSSL (CVE-2022-1292) | Extreme Portal (force.com)
"IQVA – Will not be fixed. Please upgrade to XIQ."
I'm guessing that your "Dec/Jan release" was just a joke?